StackRadar

CVE-2026-71556

High

Advisory

Published 7 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
205
of 17,781 indexed, latest versions
Container images
207
deployed by those charts
Fix available
2 of 2
affected packages

go-git: Worktree operations may follow symlinks

Carried by container images the latest versions of 205 of 17,781 indexed charts deploy, on 207 images.

Affected packageAffected versionsFixed inImages
github.com/go-git/go-git/v5golangv5.0.0, v5.1.0, v5.2.0, v5.3.0+23 more5.19.2205
github.com/go-git/go-git/v6golangv6.0.0-alpha.3, v6.0.0-alpha.4.0.20260520124234-0860a7d8a1646.0.0-alpha.52
OSV records
GHSA-hc8v-wwc9-vgxm
Also known as
GO-2026-6213

Charts affected

205 by stars
ChartLatestAffected imagesRadar Score
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-71556.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
github.com/go-git/go-git/v5@v5.13.2
5.19.2

Open the chart page →

45,239
argo-eventswenerme2.4.271 of 1See more

argo-events wenerme 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-71556.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/go-git/go-git/v5@v5.16.0
5.19.2

Open the chart page →

969
harborwenerme1.19.21 of 8See more

harbor wenerme 1.19.2

1 of the 8 container images this version deploys carry CVE-2026-71556.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.15.2215c07b71c37
github.com/go-git/go-git/v5@v5.19.1
5.19.2

Open the chart page →

1,650
mesherywenerme1.0.691 of 1See more

meshery wenerme 1.0.69

1 of the 1 container images this version deploys carry CVE-2026-71556.

Container imageDigestPackageFixed in
meshery/meshery:stable-latest9b68e81d392e
github.com/go-git/go-git/v5@v5.19.1
5.19.2

Open the chart page →

1,407
rancherwenerme2.15.11 of 2See more

rancher wenerme 2.15.1

1 of the 2 container images this version deploys carry CVE-2026-71556.

Container imageDigestPackageFixed in
rancher/shell:v0.8.1f293af9c635f
github.com/go-git/go-git/v5@v5.19.1
5.19.2

Open the chart page →

1,456

Container images carrying it

207 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
langgenius/dify-api:1.16.1dcefa5f7c47c
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
langgenius/dify-ee-plugin-connector:3.9.8-ubi91848d8f1f144
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
langgenius/dify-ee-plugin-daemon-serverless:3.9.8-ubi9d2b8df196d08
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
langgenius/dify-ee-plugin-manager:3.9.8-ubi9207b343013a0
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
github.com/go-git/go-git/v5@v5.16.2
5.19.2
1
layer5/meshery:stable-latest78a8be21bef3
github.com/go-git/go-git/v5@v5.13.2
5.19.2
1
layer5/meshery-consul:stable-latest25a4cc38abcd
github.com/go-git/go-git/v5@v5.9.0
5.19.2
1
layer5/meshery-linkerd:stable-latestb99c73bac1f5
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
layer5/meshery-osm:stable-latestec898e5786c6
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
machines/filestash:latest0b8fc005e52e
github.com/go-git/go-git/v6@v6.0.0-alpha.3
6.0.0-alpha.5
1
mesosphere/dex:v2.37.0-d2iq.1b093d78a21ed
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
mesosphere/kommander-federation-utility-apiserver:v0.21.2f9b769c65e24
github.com/go-git/go-git/v5@v5.2.0
5.19.2
1
mikejoh/argocd-extra-app-info-exporter:0.2.05c5a3b734271
github.com/go-git/go-git/v5@v5.12.0
5.19.2
1
ntakashi/gitana:1.4.04171ec641120
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
opencloudeu/opencloud:7.2.46d992ccc5f1c
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
opencsghq/gitlab-shell:v17.5.0f6d7e7d6be5d
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
owncloud/ocis:7.1.388e7c854517d
github.com/go-git/go-git/v5@v5.13.0
5.19.2
1
owncloud/ocis:8.0.1b38fd8fdd58f
github.com/go-git/go-git/v5@v5.13.0
5.19.2
1
owncloud/ocis:1.7.0d2efcae92c84
github.com/go-git/go-git/v5@v5.1.0
5.19.2
1
owncloud/server:10.16.274c53d341076
github.com/go-git/go-git/v5@v5.18.0
5.19.2
1
owncloud/server:10.16.3b3f9efdcd7f7
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
github.com/go-git/go-git/v5@v5.3.0
5.19.2
1
prowlercloud/prowler-api:5.31.14f252d579be2
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
pulumi/pulumi-kubernetes-operator:v2.5.17dace4491358
github.com/go-git/go-git/v5@v5.16.5
5.19.2
1
qualys/qscanner:5.1.0-59ff255352422
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
ryuunosukeds3/orbital:latest0879f7261b10
github.com/go-git/go-git/v5@v5.13.2
5.19.2
1
semaphoreui/semaphore:latest:v2.19.123996804607eb
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
semaphoreui/semaphore:v2.9.645b50bc11833f
github.com/go-git/go-git/v5@v5.11.0
5.19.2
1
semaphoreui/semaphore:v2.19.1498ad9bc7a2a0
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
semaphoreui/semaphore:v2.18.3e9260bfa8255
github.com/go-git/go-git/v5@v5.18.0
5.19.2
1
sikalabs/slu:v0.72.07bd267f30247
github.com/go-git/go-git/v5@v5.8.1
5.19.2
1
sikalabs/slu:v0.34.0fdc0c6711add
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
gcr.io/kaniko-project/executor:latest4e7a52dd1f14
github.com/go-git/go-git/v5@v5.16.0
5.19.2
1
gcr.io/kasten-images/restorectl:8.0.145a0884f9a90c
github.com/go-git/go-git/v5@v5.16.2
5.19.2
1
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/go-git/go-git/v5@v5.7.0
5.19.2
1
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
github.com/go-git/go-git/v5@v5.7.0
5.19.2
1
ghcr.io/cableship/argocd-source-tracker:0.0.6ff7dd45aa774
github.com/go-git/go-git/v5@v5.13.2
5.19.2
1
ghcr.io/cableship/chart-sentinel:0.1.0a037f1042b28
github.com/go-git/go-git/v5@v5.13.2
5.19.2
1
ghcr.io/caninehq/canine:latesta058034ca006
github.com/go-git/go-git/v5@v5.16.2
5.19.2
1
ghcr.io/cerbos/cerbos:0.51.08d35a64e4a99
github.com/go-git/go-git/v5@v5.16.4
5.19.2
1
ghcr.io/ckotzbauer/vulnerability-operator:0.28.167008df32715c
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1
ghcr.io/devops-ia/steampipe:v2.4.1a982103d91d3
github.com/go-git/go-git/v5@v5.17.1
5.19.2
1
ghcr.io/dexidp/dex:v2.35.313964b29d63e
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
ghcr.io/dexidp/dex:v2.44.05d0656fce7d4
github.com/go-git/go-git/v5@v5.16.0
5.19.2
1
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
github.com/go-git/go-git/v5@v5.4.2
5.19.2
1
ghcr.io/ethpandaops/syncoor:master233aa9808fc7
github.com/go-git/go-git/v5@v5.19.1
5.19.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.